Incomplete List of Disallowed Inputs in Nexus Repository Manager - CVE-2026-77124
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute previously created scripts.
The vulnerability exists due to an incomplete list of disallowed inputs in the script execution endpoint when processing requests to run stored scripts after script execution has been disabled. A remote privileged user can invoke the script execution endpoint to execute previously created scripts.
Only instances where the Script API was previously enabled and stored scripts already exist are affected.